ThreatLog forwarding doesnt work

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

ThreatLog forwarding doesnt work

Not applicable

Hi All,

I have configured the PaloAlto to email me threatn  logs for medium , high and critical alerts, but it seems to email me only medium threat alerts, how do i fix this 😞

Please find attached my log forwarding profile.

My email profile is configured fine, as i can receive system alert emails etc, but only with threat alerts, all i get is medium, even though in the threat logs there is loads of high and critical alerts.

Cheers

Bhav

6 REPLIES 6

L4 Transporter

Hi Bhav,

Can you please open up a support case for this issue.

Thanks

Hi, we have the same problem with PAN-OS 4.1.4 on an PA-2050.

But we don't get any Threat Log by mail.

With PAN-OS 4.1.3 it worked.

Is this a known issue?

Regards

Christoph

This issue should be fixed in v4.1.5.

From RN of v4.1.5

========

37608 –  Threat logs not being forwarded to the syslog server, although other logs worked
fine. Issue due to a problem with the log forwarding queue for threat logs.

========

Regards,

Emr

Thanks I will try this.

I read the RN of 4.1.5 but there was nothing with mail profile an Threat Log.

On my test with PA-500 v4.1.5.

Alert-mail is working fine.

Hopefully your PA2000 will work fine too.

I installed the 4.1.5 and now it works.

Thank you!

  • 4124 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!